Detection and Response

Patch Tuesday - July 2022

|Last updated on Jul 12, 2022|1 min read
LinkedInFacebookX
Patch Tuesday - July 2022

Microsoft’s updates for July's Patch Tuesday fix 86 CVEs, including two vulnerabilities in their Chromium-based Edge browser that were patched earlier in the month.

One 0-day vulnerability has been patched: CVE-2022-22047 affects all currently supported versions of Microsoft’s pervasive operating system. This is an elevation-of-privilege vulnerability in the Windows Client Server Runtime Subsystem (CSRSS), a critical service that is often impersonated by malware. An attacker with an already-existing foothold can exploit this vulnerability to gain SYSTEM-level privileges. Two similar vulnerabilities in CSRSS (CVE-2022-22049 and CVE-2022-22026) were also fixed, likely as a result of Microsoft’s investigation into the in-the-wild exploitation of CVE-2022-22047.

Four critical remote code execution (RCE) vulnerabilities were fixed today. CVE-2022-22029 and CVE-2022-22039 affect network file system (NFS) servers, and CVE-2022-22038 affects the remote procedure call (RPC) runtime. Although all three of these will be relatively tricky for attackers to exploit due to the amount of sustained data that needs to be transmitted, administrators should patch sooner rather than later. CVE-2022-30221 supposedly affects the Windows Graphics Component, though Microsoft’s FAQ indicates that exploitation requires users to access a malicious RDP server.

Over a third of today’s vulnerabilities (a whopping 32 CVEs) affect their Azure Site Recovery offering. Anyone making use of this VMWare-to-Azure backup solution should be sure to upgrade to version 9.49 of the Microsoft Azure Site Recovery Unified Setup, available in Update rollup 62.

Summary charts

2022-07-vuln_count_severity.png2022-07-vuln_count_impact.png2022-07-cvssv3_hist.png2022-07-vuln_count_component.png

Summary tables

Azure vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-33676Azure Site Recovery Remote Code Execution VulnerabilityNoNo7.2Yes
CVE-2022-33678Azure Site Recovery Remote Code Execution VulnerabilityNoNo7.2Yes
CVE-2022-33674Azure Site Recovery Elevation of Privilege VulnerabilityNoNo8.3Yes
CVE-2022-33675Azure Site Recovery Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-33677Azure Site Recovery Elevation of Privilege VulnerabilityNoNo7.2Yes
CVE-2022-30181Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33641Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33643Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33655Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33656Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33657Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33661Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33662Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33663Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33665Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33666Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33667Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33672Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33673Azure Site Recovery Elevation of Privilege VulnerabilityNoNo6.5Yes
CVE-2022-33642Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33650Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33651Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33653Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33654Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33659Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33660Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33664Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33668Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33669Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33671Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.9Yes
CVE-2022-33652Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.4Yes
CVE-2022-33658Azure Site Recovery Elevation of Privilege VulnerabilityNoNo4.4Yes

Azure Microsoft Dynamics vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-30187Azure Storage Library Information Disclosure VulnerabilityNoNo4.7Yes

Browser vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-2295Chromium: CVE-2022-2295 Type Confusion in V8NoNoN/AYes
CVE-2022-2294Chromium: CVE-2022-2294 Heap buffer overflow in WebRTCNoNoN/AYes

Microsoft Office vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-33633Skype for Business and Lync Remote Code Execution VulnerabilityNoNo7.2Yes
CVE-2022-33632Microsoft Office Security Feature Bypass VulnerabilityNoNo4.7Yes

System Center vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-33637Microsoft Defender for Endpoint Tampering VulnerabilityNoNo6.5Yes

Windows vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-33644Xbox Live Save Service Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-22045Windows.Devices.Picker.dll Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-30222Windows Shell Remote Code Execution VulnerabilityNoNo8.4Yes
CVE-2022-30216Windows Server Service Tampering VulnerabilityNoNo8.8Yes
CVE-2022-22041Windows Print Spooler Elevation of Privilege VulnerabilityNoNo6.8Yes
CVE-2022-30214Windows DNS Server Remote Code Execution VulnerabilityNoNo6.6Yes
CVE-2022-22031Windows Credential Guard Domain-joined Public Key Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-30212Windows Connected Devices Platform Service Information Disclosure VulnerabilityNoNo4.7Yes
CVE-2022-22711Windows BitLocker Information Disclosure VulnerabilityNoNo6.7Yes
CVE-2022-22038Remote Procedure Call Runtime Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2022-27776HackerOne: CVE-2022-27776 Insufficiently protected credentials vulnerability might leak authentication or cookie header dataNoNoN/AYes
CVE-2022-30215Active Directory Federation Services Elevation of Privilege VulnerabilityNoNo7.5Yes

Windows ESU vulnerabilities

CVETitleExploited?Publicly disclosed?CVSSv3 base scoreHas FAQ?
CVE-2022-30208Windows Security Account Manager (SAM) Denial of Service VulnerabilityNoNo6.5No
CVE-2022-30206Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-30226Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.1Yes
CVE-2022-22022Windows Print Spooler Elevation of Privilege VulnerabilityNoNo7.1Yes
CVE-2022-22023Windows Portable Device Enumerator Service Security Feature Bypass VulnerabilityNoNo6.6Yes
CVE-2022-22029Windows Network File System Remote Code Execution VulnerabilityNoNo8.1Yes
CVE-2022-22039Windows Network File System Remote Code Execution VulnerabilityNoNo7.5Yes
CVE-2022-22028Windows Network File System Information Disclosure VulnerabilityNoNo5.9Yes
CVE-2022-30225Windows Media Player Network Sharing Service Elevation of Privilege VulnerabilityNoNo7.1Yes
CVE-2022-30211Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution VulnerabilityNoNo7.5Yes
CVE-2022-21845Windows Kernel Information Disclosure VulnerabilityNoNo4.7Yes
CVE-2022-22025Windows Internet Information Services Cachuri Module Denial of Service VulnerabilityNoNo7.5No
CVE-2022-30209Windows IIS Server Elevation of Privilege VulnerabilityNoNo7.4Yes
CVE-2022-22042Windows Hyper-V Information Disclosure VulnerabilityNoNo6.5Yes
CVE-2022-30223Windows Hyper-V Information Disclosure VulnerabilityNoNo5.7Yes
CVE-2022-30205Windows Group Policy Elevation of Privilege VulnerabilityNoNo6.6Yes
CVE-2022-30221Windows Graphics Component Remote Code Execution VulnerabilityNoNo8.8Yes
CVE-2022-22034Windows Graphics Component Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-30213Windows GDI+ Information Disclosure VulnerabilityNoNo5.5Yes
CVE-2022-22024Windows Fax Service Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-22027Windows Fax Service Remote Code Execution VulnerabilityNoNo7.8Yes
CVE-2022-22050Windows Fax Service Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-22043Windows Fast FAT File System Driver Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-30220Windows Common Log File System Driver Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-22026Windows CSRSS Elevation of Privilege VulnerabilityNoNo8.8Yes
CVE-2022-22047Windows CSRSS Elevation of Privilege VulnerabilityYesNo7.8Yes
CVE-2022-22049Windows CSRSS Elevation of Privilege VulnerabilityNoNo7.8Yes
CVE-2022-30203Windows Boot Manager Security Feature Bypass VulnerabilityNoNo7.4Yes
CVE-2022-22037Windows Advanced Local Procedure Call Elevation of Privilege VulnerabilityNoNo7.5Yes
CVE-2022-30202Windows Advanced Local Procedure Call Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-30224Windows Advanced Local Procedure Call Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-22036Performance Counters for Windows Elevation of Privilege VulnerabilityNoNo7Yes
CVE-2022-22040Internet Information Services Dynamic Compression Module Denial of Service VulnerabilityNoNo7.3Yes
CVE-2022-22048BitLocker Security Feature Bypass VulnerabilityNoNo6.1Yes
CVE-2022-23825AMD: CVE-2022-23825 AMD CPU Branch Type ConfusionNoNoN/AYes
CVE-2022-23816AMD: CVE-2022-23816 AMD CPU Branch Type ConfusionNoNoN/AYes

NEVER MISS A BLOG

Get the latest stories, expertise, and news about security today.

Subscribe

Related blog posts